CVE-2023-4408
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Bind 9, Bind Server, Centos, Ibm Aix, Linuxmint
- Netapp Ontap
- = 9.14.1, 9.15.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-407
- NVD status
- Modified
- Published
- 2024-02-13
Fix
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.48, 9.18.24, 9.19.21, 9.16.48-S1, or 9.18.24-S1.
Workaround
No workarounds known.
No indexed exploits for CVE-2023-4408 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-4408 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.